Movatterモバイル変換


[0]ホーム

URL:


CN106997533B - POS terminal product safety production authorization management system and method - Google Patents

POS terminal product safety production authorization management system and method
Download PDF

Info

Publication number
CN106997533B
CN106997533BCN201710213016.4ACN201710213016ACN106997533BCN 106997533 BCN106997533 BCN 106997533BCN 201710213016 ACN201710213016 ACN 201710213016ACN 106997533 BCN106997533 BCN 106997533B
Authority
CN
China
Prior art keywords
card
production
terminal
authorization
pos terminal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201710213016.4A
Other languages
Chinese (zh)
Other versions
CN106997533A (en
Inventor
叶华峰
柳希玲
陈帆
游锦云
罗才生
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Fujian Start Computer Equipment Co ltd
Original Assignee
Fujian Start Computer Equipment Co ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Fujian Start Computer Equipment Co ltdfiledCriticalFujian Start Computer Equipment Co ltd
Priority to CN201710213016.4ApriorityCriticalpatent/CN106997533B/en
Publication of CN106997533ApublicationCriticalpatent/CN106997533A/en
Application grantedgrantedCritical
Publication of CN106997533BpublicationCriticalpatent/CN106997533B/en
Activelegal-statusCriticalCurrent
Anticipated expirationlegal-statusCritical

Links

Images

Classifications

Landscapes

Abstract

The invention relates to a POS terminal product safety production authorization management system and a method, wherein the system comprises a set of intelligent IC cards for storing authorization information; the POS terminal card sender is used for authorizing and issuing the intelligent IC card and auditing production authorization information; the production management server is in network communication with the POS terminal card sender so as to support the management, use and production information acquisition of the POS terminal card sender; a production test program for completing all functional tests in the production process of the POS terminal; and a production authorization program for verifying the test result, controlling the production quantity after the mutual authentication between the terminal and the card, and completing the generation and downloading of the terminal hardware serial number and the initial transmission key. The management system and the management method solve the management problem that sensitive information can not be leaked out for the product quality and safety protection of the control terminal when the POS terminal manufacturer produces in a factory off-line mode.

Description

POS terminal product safety production authorization management system and method
Technical Field
The invention relates to the field of POS terminal production management, in particular to a POS terminal product safety production authorization management system and a POS terminal product safety production authorization management method.
Background
With the popularization of financial POS terminals, the gradual perfection of card environments and the gradual realization of the electronization of social consumption settlement, the effective safety control of the financial POS terminals becomes an extremely important aspect. Since this year, the compulsory bank issues a strengthened bank card POS acceptance terminal security management, and the union pay of China issues and implements "the life cycle security and quality management guideline of union pay card acceptance terminal products", which puts higher requirements on the life cycle management security and quality management of the terminal, and the terminal manufacturer must ensure that:
(1) before leaving the factory, the terminal must be ensured to be subjected to function test and safety test.
(2) The unique terminal hardware serial number must be factory stored in a secure area and cannot be read and modified.
(3) Security holes caused by leakage of sensitive information are prevented in the production process.
(4) If the outsourcing mode is substituted, the quality control of the terminal needs to be ensured, and the terminal is ensured to leave the factory safely.
The existing POS terminal manufacturer product production management process mainly comprises two types:
and (3) online production: before delivery, the terminal transmits the production test result on the internet, the server authorizes the terminal, packages the terminal after authorization is completed, and then stores the terminal in a warehouse after OQC inspection. This model is highly demanding on the network environment of the factory production line.
Off-line production: before delivery, the production test result is manually checked, checked and packaged, and then the product is warehoused after OQC inspection. The mode has high requirements on personnel quality and personnel management.
Disclosure of Invention
In view of the above, an object of the present invention is to provide a system and a method for managing authorization of POS terminal product safety production, which can control product quality and also control safety of products in a production process, solve a management problem that sensitive protection information for controlling the product quality and safety of a terminal cannot be leaked when a POS terminal manufacturer performs off-line production in a factory, and are particularly suitable for safety production management of an outsourced factory of the POS terminal manufacturer.
The invention is realized by adopting the following scheme: the utility model provides a POS terminal product safety production authorizes management system which characterized in that: comprises a set of intelligent IC card for storing authorization information; the POS terminal card sender is used for authorizing and issuing the intelligent IC card and auditing production authorization information; the production management server is in network communication with the POS terminal card sender so as to support the management, use and production information acquisition of the POS terminal card sender; a production test program for completing all functional tests in the production process of the POS terminal; and a production authorization program for verifying the test result, controlling the production quantity after the mutual authentication between the terminal and the card, and completing the generation and downloading of the terminal hardware serial number and the initial transmission key.
The invention is also realized by adopting the following scheme: a POS terminal product safety production authorization management method comprises the following steps:
step S1: providing a set of intelligent IC cards for user authorization for a production management specialist, and distributing a user name and a login password which are uniquely corresponding to the intelligent IC cards for authorization management operation of the intelligent IC cards;
step S2: issuing a production according to the order requirement, and transmitting a production authorization packet to a POS terminal card sender special for a factory through a network, wherein the production authorization packet comprises ciphertext data of work order information;
step S3: the production management specialist issues card authorization to the intelligent IC card through the POS terminal card sender according to the order number, and after card issuing is completed, the production authorization packet on the POS terminal card sender fails and cannot issue cards any more;
step S4: in the production process, the production authorization program automatically judges the production test result, and controls the production quantity of the terminal by mutually authenticating with the card, automatically generates a terminal hardware serial number and a terminal initial transmission key, stores the terminal hardware serial number and the terminal initial transmission key in a security module of the terminal, and stores the terminal authorization information in an authorization card;
step S5: and the POS terminal card sender examines the terminal authorization information, outputs an examination result and uploads the terminal information to the production management system through a network.
Furthermore, the intelligent IC card authorizes a production management specialist for management, is only dedicated for authorized management, authorizes a terminal for production, and performs production authorization examination.
Further, the work order information in the production authorization packet includes a production management specialist, a product model, a quantity, a sub serial number, an initial transmission root key and a ciphertext storage. The production authorization packet is transmitted to the factory-specific POS terminal card sender through the network.
Further, in step S3, performing card issuing authorization includes the following steps:
step S31: inserting the intelligent IC card into an IC card slot of a POS terminal card sender by a production management specialist, inputting a user name and a password of the production management specialist, locking the card sender for 2 hours for 5 times with the maximum error trial frequency exceeding 5 times, and recording and uploading alarm information;
step S32: the POS terminal card sender verifies the card validity by using the solidified card public key, reads the user name of a production manager in the card after the card passes the validity and compares the user name with the current user name, and enters the next step of processing after the comparison is consistent; otherwise, refusing, recording and uploading alarm information.
Step S33: inputting a card password, automatically locking the card for 5 times with the maximum error attempt times and more than 5 times, and recording and uploading alarm information by the card sender; after the card password passes the verification, selecting a card authorization menu;
step S34: and inputting the work order number, and the POS terminal card sender writes the intelligent IC card to finish authorization, wherein the authorization content comprises the product model number, the product quantity, the hardware serial number and the initial transmission root key.
Further, the step S4 is specifically:
step S41: an authorization card is inserted into each terminal card slot, and an authorization management and control program automatically judges whether the terminal completes all function tests or not, so that the normal functions of the terminal are ensured;
step S42: the terminal reads the IC card and checks whether the product model is in accordance with the IC card;
step S43: the terminal reads the current producible quantity of the cards, and if the production quantity is 0, authorization is refused; otherwise, the production quantity of the card is automatically reduced by 1 to prevent illegal production;
step S44: the terminal reads the hardware serial number distributed by the card and writes the hardware serial number to a security module of the terminal to ensure that one machine has one number for preventing the serial number from being illegally tampered; the method for generating the hardware serial number comprises the following steps: and reading the manufacturer code number, the terminal type and the manufacturer sub-serial number in the card, and generating a 10-byte terminal random factor by the terminal security module.
Step S45: the IC card generates a terminal initial transmission key according to a dispersion algorithm, then writes the terminal initial transmission key into the security module, and then writes the terminal random factor into the authorization card;
step S46: and the terminal completes production authorization and deletes the production test program.
Further, the step S5 is specifically:
step S51: inserting the intelligent IC card into an IC card slot of a POS terminal card sender by a production management specialist, inputting a user name and a password of the production management specialist, locking the card sender for 2 hours for 5 times with the maximum error trial frequency exceeding 5 times, and recording and uploading alarm information;
step S52: the POS terminal card sender verifies the card validity by using the solidified card public key, reads the user name of a production manager in the card after the card passes the validity and compares the user name with the current user name, and enters the next step of processing after the comparison is consistent; otherwise, refusing, recording and uploading alarm information.
Step S53: inputting a card password, automatically locking the card for 5 times with the maximum error attempt times and more than 5 times, and recording and uploading alarm information by the card sender; after the card password passes the verification, selecting an authorization verification menu;
step S54: inputting a work order number, reading the authorization information of the intelligent IC card terminal by the POS terminal card sender, comparing the authorization information with the authorization information of planned production, and outputting an auditing result;
step S55: and uploading the terminal information (the serial number of the terminal hardware, the test result, the yield, the production time and the like) to the production management system through the network.
Compared with the prior art, the invention has the following beneficial effects: compared with the traditional off-line production process, the method provided by the invention has the advantages that the stages of user authorization, authorized card issuing, authorized control and production authorization verification are added, all sensitive data in the whole process are safely stored in the intelligent IC card, and the security loophole caused by the leakage of the sensitive data is prevented. Through card authorization, the output of the POS terminal of the factory is strictly controlled, and illegal production is prevented. The hardware serial number is automatically distributed, a first machine is guaranteed, the POS terminal uploads the hardware serial number to a Unionpay terminal information verification system after leaving a factory, the POS terminal is guaranteed to be in production, application, maintenance and other links, meanwhile, the unique hardware serial number of the terminal cannot be tampered and imitated in application rules, and the problems that the POS terminal is illegally modified and the POS terminal receives a bill and the like at the present stage are solved. The terminal initial transmission key is automatically generated by adopting a symmetric key SM4 algorithm dispersion algorithm, and one secret is ensured.
Drawings
FIG. 1 is a flow diagram of a conventional off-line production process;
FIG. 2 is a flow chart of the production summary of the present invention;
FIG. 3 is a flow chart of an authorized card issuance process in accordance with the present invention;
FIG. 4 is a flow chart of card authorization management and control in the present invention;
FIG. 5 is a flow chart of the card production authorization audit of the present invention;
fig. 6 shows the encoding format of the serial number of the terminal hardware in the present invention.
Detailed Description
The invention is further explained below with reference to the drawings and the embodiments.
The production management process of the POS terminal product provided in this embodiment is mainly divided into 8 stages: user authorization, issuing a bill, authorizing card issuing before production, assembling + general inspection, card authorization control, production authorization verification, OQC and warehousing, as shown in figures 2-3, and figure 1 is a traditional off-line production flow chart.
1. And (4) user authorization. And distributing an intelligent IC card to a production management specialist, and distributing a user name and a login password which are uniquely corresponding to the IC card for subsequent use of the IC card for authorization management operation, wherein the IC card is managed by the specialist only for authorization management.
2. And (5) producing a hair slip. And issuing a production according to the order requirement, and transmitting the production authorization packet to a factory-dedicated POS terminal card sender through a network. The production authorization packet contains ciphertext data of the work order information, and the production authorization packet comprises the following steps: production management specialist, product model, number, sub serial number, initial transmission root key.
3. Authorizing and issuing the card, wherein after the authorization is finished, the production authorization package stored in the card issuing machine can not issue the card any more.
(1) Inserting a card into an IC card slot of a POS terminal card sender by a production management specialist, inputting a user name and a password of the production management specialist, locking the card sender for 2 hours for more than 5 times with 5 times of maximum error attempts, and recording and uploading alarm information;
(2) and the card sender verifies the validity of the card by using the solidified public key of the card, reads the user name of the production manager in the card after the validity passes and compares the user name with the current user name, and the next step is carried out after the comparison is consistent. Otherwise, refusing to record and upload alarm information;
(3) inputting a card password, automatically locking the card for 5 times with the maximum error attempt times and more than 5 times, and recording and uploading alarm information by the card sender; and after the card password passes the verification, selecting a card authorization menu.
(4) And inputting the work order number, and the card sender writes the IC card to finish authorization. The authorization content includes: product model, product quantity, hardware serial number, initial transmission root key.
4. And (5) carrying out assembly inspection and general inspection on the product, and detecting that all modules of each terminal have normal functions.
5. And (5) card authorization management and control.
(1) And when an authorization card is inserted into each terminal card slot, the authorization management and control program can automatically judge whether the terminal completes all function tests, so that the normal functions of the terminal are ensured.
(2) The terminal reads the IC card and checks whether the product model is in accordance with the IC card.
(3) The terminal reads the number of cards that can currently be produced. If the producibility is 0, authorization is denied. Otherwise, the production quantity of the card is automatically reduced by 1, so that illegal production can be prevented.
(4) The terminal reads the hardware serial number distributed by the card and writes the hardware serial number to the security module of the terminal, so that one machine is ensured, and the serial number is prevented from being illegally tampered. The method for generating the hardware serial number comprises the following steps: and reading the manufacturer code number, the terminal type and the manufacturer sub-serial number in the card, generating a 10-byte terminal random factor by the terminal security module, and generating according to the rule of FIG. 6.
(5) The IC card generates a terminal initial transmission key according to the following dispersion algorithm, and then writes the terminal initial transmission key into the security module, so that one machine is ensured, and sensitive information is prevented from being leaked. The dispersion algorithm is as follows:
1) a terminal hardware serial number (50B), right complement 0x 800 x 000 x 000 x 000 x 000 x00, constituting 56B extended serial number;
2) the extended sequence number is divided into 4 blocks (M0, M1, M2, M3) by one block every 16B;
3) encrypting the M0 block with the initial transport root key using the SM4 algorithm to generate TM0
4) Performing exclusive or on the TM0 block and the M1 block to generate an N1 block;
5) encrypting the N1 block by using an SM4 algorithm by using an initial transmission root key to generate a TM1 block;
6) performing exclusive or on the TM1 block and the M2 block to generate an N2 block;
7) encrypting the N2 block by using an SM4 algorithm by using an initial transmission root key to generate a TM2 block;
8) performing exclusive or on the TM2 block and the M3 block to generate an N3 block;
9) encrypting the N3 block by using an SM4 algorithm by using an initial transmission root key to generate a TM3 block;
TM3 serves as the terminal initial transport key.
(6) And the terminal completes production authorization and deletes the production test program.
6. And (6) production authorization auditing.
(1) After production is finished, a production manager inserts the IC card into a POS terminal card sender, and firstly, a user name and a password of a production manager are input; inputting the IC card password; and selecting a production audit menu and inputting a work order number.
(2) The card sender reads the production authorization information in the card, compares the production authorization information with the authorization information planned for production, outputs an auditing result, and uploads terminal information (a terminal hardware serial number, a test result, yield, production time and the like) to a production management system through a network.
7. And after the OQC detection is finished, the terminal finishes warehousing.
The above description is only a preferred embodiment of the present invention, and all equivalent changes and modifications made in accordance with the claims of the present invention should be covered by the present invention.

Claims (5)

1. The utility model provides a POS terminal product safety production authorizes management system which characterized in that: comprises a set of intelligent IC card for storing authorization information; the POS terminal card sender is used for authorizing and issuing the intelligent IC card and auditing production authorization information; the production management server is in network communication with the POS terminal card sender so as to support the management, use and production information acquisition of the POS terminal card sender; a production test program for completing all functional tests in the production process of the POS terminal; a production authorization program for verifying the test result, controlling the production quantity after the mutual authentication between the terminal and the card, and completing the generation and downloading of the terminal hardware serial number and the initial transmission key;
CN201710213016.4A2017-04-012017-04-01POS terminal product safety production authorization management system and methodActiveCN106997533B (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN201710213016.4ACN106997533B (en)2017-04-012017-04-01POS terminal product safety production authorization management system and method

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN201710213016.4ACN106997533B (en)2017-04-012017-04-01POS terminal product safety production authorization management system and method

Publications (2)

Publication NumberPublication Date
CN106997533A CN106997533A (en)2017-08-01
CN106997533Btrue CN106997533B (en)2020-10-13

Family

ID=59435021

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN201710213016.4AActiveCN106997533B (en)2017-04-012017-04-01POS terminal product safety production authorization management system and method

Country Status (1)

CountryLink
CN (1)CN106997533B (en)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN110445749B (en)*2019-06-122022-04-01冯威Method for authorizing product production
CN110995421B (en)*2019-11-292022-12-06福建新大陆支付技术有限公司POS terminal one-machine one-secret automatic secret key installation method
CN111859359B (en)*2020-06-042024-10-11青岛海信智慧家居系统股份有限公司Intelligent device authorization system, method, device, equipment and medium
CN114172649B (en)*2022-02-112022-05-13厚普智慧物联科技有限公司Cloud key management method and system based on intelligent IC card security authentication

Citations (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN103716167A (en)*2013-03-152014-04-09福建联迪商用设备有限公司Method and device for safely collecting and distributing transmission keys
CN103903078A (en)*2012-12-282014-07-02贵州久联民爆器材发展股份有限公司Mixed loading explosive truck intelligent production management and control method and device
CN105678179A (en)*2014-11-202016-06-15广东华大互联网股份有限公司Issuing method of IC card internet terminal and management system
US20160210629A1 (en)*2015-01-192016-07-21Lg Cns Co., Ltd.Management server, card authorization terminal, and methods of processing a card in the management server and the card authorization terminal

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN103903078A (en)*2012-12-282014-07-02贵州久联民爆器材发展股份有限公司Mixed loading explosive truck intelligent production management and control method and device
CN103716167A (en)*2013-03-152014-04-09福建联迪商用设备有限公司Method and device for safely collecting and distributing transmission keys
CN105678179A (en)*2014-11-202016-06-15广东华大互联网股份有限公司Issuing method of IC card internet terminal and management system
US20160210629A1 (en)*2015-01-192016-07-21Lg Cns Co., Ltd.Management server, card authorization terminal, and methods of processing a card in the management server and the card authorization terminal

Also Published As

Publication numberPublication date
CN106997533A (en)2017-08-01

Similar Documents

PublicationPublication DateTitle
CN108053001B (en)Information security authentication method and system for electronic warehouse receipt
JP6356896B2 (en) System and method for creating fingerprint of encryption device
CN100533427C (en) remote access system
CN100492966C (en)Identity certifying system based on intelligent card and dynamic coding
CN106997533B (en)POS terminal product safety production authorization management system and method
US20080224823A1 (en)Identification Systems
CN104104672A (en)Method for establishing dynamic authorization code based on identity authentication
US20060149972A1 (en)Method for realizing security storage and algorithm storage by means of semiconductor memory device
KR101051420B1 (en) Safety OTP generation device and method
US10700868B2 (en)Security systems and methods for electronic devices
CN106682905B (en)Application unlocking method
US20180375847A1 (en)Stored value user identification system using blockchain or math-based function
CN106533693A (en)Access method and device of railway vehicle monitoring and maintenance system
CN112884485A (en)Symmetric encryption traceability transaction method, system and storage medium based on block chain network
CN101425901A (en)Control method and device for customer identity verification in processing terminals
CN109889343A (en)Electronic invoice circulation control method and device
CN118967159A (en) An anti-counterfeiting traceability system and anti-counterfeiting method based on electronic tags
CN112910886B (en) A method and system for verifying the identity of a lock
CN102315944A (en)Seed key multi-time injection dynamic token, dynamic password authentication system and method
CN107493167A (en)Terminal key dissemination system and its terminal key distribution method
CN101588243A (en)A kind of electronic transaction historical record querying method and system
CN1848726A (en)Dynamic identifying method
CN101304422B (en)Method for improving identification authentication security based on password card
CN101304316B (en)Method for improving identification authentication security based on password card
CN119941258B (en) Transaction information management method and device based on blockchain

Legal Events

DateCodeTitleDescription
PB01Publication
PB01Publication
SE01Entry into force of request for substantive examination
SE01Entry into force of request for substantive examination
GR01Patent grant
GR01Patent grant

[8]ページ先頭

©2009-2025 Movatter.jp